DNS Root KSK Rollover: Critical Event for Internet Trust on October 11
The DNS root is set to undergo its second-ever Key-Signing Key (KSK) rollover on October 11, 2026, a critical event for DNSSEC validation that requires attention from DNS resolver operators to prevent widespread website inaccessibility.

On October 11, 2026, a pivotal event for the internet's infrastructure will occur: the DNS root is scheduled to perform its second-ever Key-Signing Key (KSK) rollover. This process is fundamental to the security and integrity of the Domain Name System (DNS) through DNS Security Extensions (DNSSEC). DNSSEC allows DNS resolvers to cryptographically verify the authenticity of DNS responses, ensuring that users are directed to legitimate websites and not malicious imposter sites. The KSK is the root of trust for this entire validation process, and its rollover means the cryptographic anchor point for DNSSEC is changing.
For the vast majority of internet users and website operators, no action will be required. However, the rollover poses a significant risk to those operating DNSSEC-validating resolvers. If these resolvers do not trust the new KSK before it becomes active, they will be unable to validate DNS responses originating from the root zone. This failure in validation will effectively make many websites unreachable for users relying on those resolvers, even if the websites themselves are functioning correctly. This was a concern during the first KSK rollover in 2018, where some resolvers lost their established trust in the new key, particularly after software upgrades or migrations.
The DNS root zone, unlike other DNS zones, has no parent zone to vouch for its keys. Instead, DNSSEC validation begins with a pre-configured, trusted public key or its fingerprint, known as a trust anchor. The root zone uses two types of keys: the Zone-Signing Key (ZSK) signs the root's DNS records, including the Delegation Signer (DS) records for top-level domains (TLDs) like .com. The Key-Signing Key (KSK) is responsible for signing the root's DNSKEY record set, which contains the public keys used for validation, including the ZSK. Resolvers use their trusted KSK to verify the integrity of the DNSKEY set and then use the ZSK from that set to validate other root zone records.
The new key, designated KSK-2024 with key tag 38696, will replace the current KSK-2017 (key tag 20326). The process for resolvers to adopt a new trust anchor is defined by RFC 5011, which allows for automatic learning of new root trust anchors. The root publishes the new KSK alongside the old one in its DNSKEY set. Resolvers can then use the existing, trusted KSK to verify the DNSKEY records that include the new KSK. After a minimum waiting period of 30 days, during which the new key must remain consistently published and verifiable, the resolver can automatically update its trust anchor.
To mitigate the risks observed in 2018, Cloudflare has proactively updated its resolver software to include KSK-2024 directly in its built-in trust anchors since July 2024. This ensures that resolvers running the updated software have the new anchor available from the outset, reducing reliance on the automatic RFC 5011 learning process, which can be susceptible to issues during software updates or system migrations. This approach aims to prevent the loss of trust-anchor state that affected some resolvers during the previous rollover.
To assist operators in verifying their readiness, Cloudflare has implemented a test based on RFC 8509, the Root Key Trust Anchor Sentinel for DNSSEC. This test allows users to query their resolver to determine if it trusts the new KSK-2024. By visiting Cloudflare's rollover readiness test page, users can check if the resolver their browser is using has successfully incorporated the new key. This proactive testing is crucial for ensuring the stability and accessibility of the internet's domain name system as the KSK rollover approaches.
While the technical details of DNSSEC and KSK rollovers might seem obscure, the implications are far-reaching. A successful rollover ensures the continued security and reliability of the internet's addressing system. Conversely, a failure could lead to significant disruptions, impacting businesses, services, and users globally. The proactive measures taken by organizations like Cloudflare, combined with diligent checks by resolver operators, are essential to navigating this critical infrastructure event smoothly.